Pazmo covers what it can detect online, lets you self-report what it can't, and guides the rest. It never determines or certifies compliance — this shows readiness coverage only.
ISO/IEC 27001:2022
Control-mappedThe spine other frameworks crosswalk to.
- Detected now
- 22checks
- You self-report
- 15items
- Via connections
- 4areas
- Guidance
- 3areas
Coming via connections (GitHub / cloud)
- ·Source-code access & secure coding (A.8.4 / A.8.28)
- ·Technical vulnerability mgmt — dependencies/CVEs (A.8.8)
- ·Change management — branch protection (A.8.32)
- ·Logging & monitoring (A.8.15 / A.8.16)
Pazmo guides (process controls)
- ·Security policy, asset inventory, supplier security (A.5)
- ·Risk assessment & treatment process
- ·Secure SDLC & data-leakage prevention (A.8.25–A.8.31)
Out of scope: Physical controls (A.7) and personnel/hiring checks.
SOC 2 (Trust Services Criteria)
Control-mappedCommon Criteria mostly crosswalks onto the ISO spine.
- Detected now
- 10checks
- You self-report
- 15items
- Via connections
- 2areas
- Guidance
- 1areas
Coming via connections (GitHub / cloud)
- ·Logical access & change management (CC6 / CC8)
- ·Vulnerability detection & monitoring (CC7)
Pazmo guides (process controls)
- ·Control environment, risk assessment, vendor management (CC1–CC5, CC9)
Out of scope: Physical security and HR processes.
GDPR
Crosswalk pendingArticle-based; transport encryption & access map to Art. 32 readiness.
- Detected now
- 0checks
- You self-report
- 15items
- Via connections
- 1areas
- Guidance
- 1areas
Coming via connections (GitHub / cloud)
- ·Access control & encryption-at-rest evidence (Art. 32)
Pazmo guides (process controls)
- ·Lawful basis, data-subject rights, records of processing, DPA with vendors
Out of scope: Legal determinations and organizational data-governance.
ISO/IEC 27701 (Privacy)
Crosswalk pendingExtension of the ISO 27001 spine.
- Detected now
- 0checks
- You self-report
- 15items
- Via connections
- 0areas
- Guidance
- 1areas
Pazmo guides (process controls)
- ·PII processing controls extending ISO 27001 — mostly policy/process
Out of scope: Privacy governance and legal roles.
HIPAA Security Rule
Crosswalk pendingScope-gated; relevant only if you handle PHI.
- Detected now
- 0checks
- You self-report
- 15items
- Via connections
- 1areas
- Guidance
- 1areas
Coming via connections (GitHub / cloud)
- ·Audit logging & access controls (Technical Safeguards)
Pazmo guides (process controls)
- ·Administrative safeguards — policies, training, BAAs
Out of scope: Physical safeguards and workforce procedures.
AI App Safety
Crosswalk pendingNot a formal audit framework.
- Detected now
- 0checks
- You self-report
- 0items
- Via connections
- 1areas
- Guidance
- 1areas
Coming via connections (GitHub / cloud)
- ·AI app static checks — prompt/output handling (Phase 3)
Pazmo guides (process controls)
- ·Model usage policy, output validation, abuse monitoring
Out of scope: No formal control catalogue exists; handled as guidance + static checks.
EN 18031 (Radio equipment)
Crosswalk pendingScope-gated; shown only when declared.
- Detected now
- 0checks
- You self-report
- 0items
- Via connections
- 0areas
- Guidance
- 0areas
Out of scope: Device/firmware standard — largely not applicable to web/SaaS.
Readiness coverage only — Pazmo does not determine or certify compliance.